The Three Lines Model Explained: The 2026 IIA Update
How the IIA three lines model works in banks and credit unions, what changed in the 2026 update, and why assurance and advice must be kept distinct.
8 min read · From the course Enterprise Risk Management in US Banks and Credit Unions with Python
The three lines model is a governance framework from the Institute of Internal Auditors. It answers three questions: who owns a risk, who oversees it, and who independently checks that any of it is true. Management owns and manages risk, second line roles bring expertise, monitoring and challenge, and internal audit provides independent assurance. The current version is a statement of position issued in July 2026. It replaces the 2020 model and is built around the difference between assurance and advice.
The problem the three lines model solves
The people running a business know its risks better than anybody. They see the customers, they price the deals, and they know which systems are held together with tape. Nobody else has that knowledge. But the same people are paid to take those risks, are judged on the results, and would rather not discover that a process is broken. That makes them the worst possible judges of their own controls. They are not dishonest, just human and structurally conflicted.
An outsider is objective but knows almost nothing. By the time they have learned enough, they have stopped being an outsider. Proximity and objectivity pull in opposite directions, and the tension does not resolve.
The model's answer is a piece of organizational design. It does not look for people who are somehow both close and detached. Instead, it stops asking any single group to supply both. It sets up several roles at different distances from the risk and is explicit about which distance each one occupies. That is the whole idea, and everything else is detail.
The three roles and the board
- First line: management. Management owns and manages risks and is responsible for the design and operation of processes and controls. The business owns the risk, not the risk department. A risk function that takes ownership away from the business makes things worse while appearing to make them better.
- Second line roles. These provide specialized expertise, support, monitoring and challenge to improve risk management, compliance and control practices. In a bank, this is where the risk function sits, along with compliance and often cyber and financial crime.
- Third line: internal audit. Internal audit provides independent and objective assurance on the effectiveness of governance, risk management, compliance and control processes. The current statement adds that it also provides advisory insights while not assuming management responsibility.
Above all three sits the board, which is the audience for all of it. The 2026 statement says it is intended for an executive audience rather than primarily for internal auditors, and its principles are written around what boards need. That is a real change of emphasis: the statement is written for the people receiving assurance rather than for the people producing it.
The model describes functions, not an organization chart. Second line roles can sit in several places, and in a smaller institution one person may hold more than one of them.
Assurance versus advice
The 2026 update is built on separating assurance from advice. The statement treats them as distinct but complementary.
Assurance asks whether something is working as intended. It looks at what has happened and what is happening. It requires independence, because its value depends on the person giving it having nothing to gain. It produces a conclusion the board can rely on.
Advice asks how something could be better. It is forward looking. Proximity and expertise matter more than independence, and it produces options rather than a verdict.
The practical point is that you cannot give independent assurance over your own work. If internal audit helped design a control, it cannot then independently conclude that the control is effective, because it would be reviewing itself. The statement calls this a self-review threat. Institutions argue about this all the time. Audit found the problem and understands it best, so it gets asked to help fix it. Once it does, the organization can no longer get independent assurance on the fix.
The five principles of the 2026 statement
- The board sets purpose, risk appetite and expectations and oversees the pursuit of strategic objectives. Risk appetite appears in the very first principle, which shows how central it is.
- Effective oversight depends on reliable, balanced information on performance, risks and controls. The key word is balanced, not comprehensive or voluminous. Reporting that is technically complete but gives no sense of proportion fails this principle.
- The board and senior management establish accountability by defining roles and responsibilities. Accountability does not arise on its own.
- Distinct sources of assurance, including from an independent source, give boards confidence that governance, risk management, compliance and control processes are working as intended, achieving objectives and promoting timely corrective actions. Assurance that identifies a problem but leads to no correction does not satisfy this principle.
- Advisory services complement assurance by providing insights, perspectives and options that support improvement and informed decision making. They complement assurance. They do not replace or compromise it.
From three lines of defense to the three lines model
The model has had three forms. It began as the three lines of defense, the phrase most banking material still uses. In 2011 the Basel Committee wrote that common industry practice for sound operational risk governance often relies on three lines of defense: business line management, an independent corporate operational risk management function, and independent review. Basel was not proposing the model. It was reporting what banks already did.
In 2020 the Institute rewrote the model. It dropped the word defense, brought the governing body explicitly into the model, and set out six principles. Its subtitle called it an update of the three lines of defense. The 2020 paper asked organizations to focus on the contribution risk management makes to achieving objectives and creating value, as well as to matters of defense and protecting value. The objection is not that defense sounds negative. It is that a purely defensive frame leaves out half of what the discipline is for. Acme Bank's commercial real estate concentration is not an assault on Acme Bank. It is the business Acme Bank chose. A frame that treats every exposure as an incoming attack pushes the whole apparatus toward refusing things, and refusing things is not what the institution is paying for.
In July 2026 the 2020 version was itself replaced. The five principles are not the six with one taken out. They are a different set, organized around assurance and advice rather than around the lines themselves. The document actually grew, adding a whole second part on putting the model into practice.
When a colleague, examiner or policy document says three lines of defense, they mean substantially the same three roles. Do not correct them, but know which document is current.
Banks, credit unions and overlapping roles
The Institute of Internal Auditors is the professional body for internal auditors in every sector, and the statement says its principles apply to all organizations. This is not banking guidance. It reaches a credit union exactly as it reaches a bank.
Two fictional teaching institutions make this concrete. At Acme Bank, the first line is the lenders, treasury, operations and the branch network. The second line is the risk function, compliance, cyber and financial crime, headed by the chief risk officer. The third line is internal audit, which reports to the audit committee of the board. A board risk committee sits above the second line.
At Acme Credit Union, the first line is lending, member services and operations. The second line is risk and compliance, which is usually smaller and less subdivided. The third line is internal audit, alongside the supervisory committee. The credit union has no chief risk officer mandate, but someone there still does second line work. Somebody sets limits, monitors compliance and challenges lending decisions. A smaller institution does not have fewer lines. It has the same lines held by fewer people, sometimes one person wearing two hats.
Where internal audit takes on a second line responsibility, the statement says this creates a direct self-review threat. It says the arrangement should be carefully considered, periodically reevaluated and fully transparent. Its safeguards are:
- Clear, documented justification that the arrangement is necessary.
- Full disclosure to the board of the responsibility being assumed and the risk it creates.
- Another independent party, internal or external, providing assurance over that area for as long as the overlap lasts.
A parallel set applies when the chief audit executive supervises another assurance or compliance function. Keep the supervised function's operational work separate from audit's own assurance work, and document who is responsible for what. Have anything audit supervises independently reviewed from time to time, and get board approval for the expanded remit. Keep talking whenever an objectivity concern comes up. The approach is to manage these arrangements, not to prohibit them. The real failure is an overlap that nobody declared.
Five ways the model fails
- The first line believes risk belongs to the second line. Ownership evaporates, and the second line ends up doing a job it cannot do at the scale required.
- The second line writes policy that nobody follows and counts the policy as a control. A policy is not a control. A control is something that actually happens.
- The third line audits process compliance rather than whether risk is actually managed. Testing that a form was completed produces comfort rather than assurance.
- Findings are agreed, actioned late and never retested. A finding that closes because the deadline passed satisfies nothing.
- Everybody is independent and nobody talks to anybody else. Each function assumes another is covering the gaps, so the same control gets tested three times and something else never gets tested. The statement says independence must not lead to isolation or fragmented insights.
Key takeaways
- The three lines model resolves the tension between proximity and objectivity by assigning roles at different distances from the risk.
- Management owns risk, second line roles provide expertise and challenge, and internal audit provides independent assurance.
- The July 2026 statement has five principles and is built on the difference between assurance and advice. If you count six, you are reading the 2020 version.
- You cannot give independent assurance over your own work.
- The lines are roles, not departments. Small institutions have the same lines held by fewer people.
- Overlaps should be justified, disclosed to the board and covered by another independent source of assurance.
More from Enterprise Risk Management
Educational content only, not legal, accounting or investment advice.